PT-2026-71631 · Rsync · Rsync
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 3.5.0
Description
A path confinement bypass allows remote clients to escape the intended inner-module root confinement. This occurs when the module root contains a
/./ boundary marker, enabling the construction of paths that resolve outside the chroot boundary. Attackers can exploit the improper handling of the /./ notation or forge delta-basis transfers referencing xname paths that cross the /./ boundary to obtain unauthorized read or write access to files outside the module's subtree.Recommendations
Update rsync to version 3.5.0 or later.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsync